LINUX.ORG.RU

Сообщения vaga

 

Strongswan 5.0.4 + certificate

Форум — Admin

Господа, прошу помощи, устал уже ковырять, не вижу причину. Может кто сталкивался. Описание системы и проблемы:

centos x86-64 обновленная
strongswan-5.0.4-4.el6.x86_64
openssl-1.0.0-27.el6_4.2.x86_64
ipsec + ikev2 = двухсторонняя аутентификация сертификатами, и насколько я вижу, с ней все порядке. Проблема так же и не в Iptables, т.к. пробовал локально, там фаер полностью открыт. Пробовал уже аутентификацию клиента через пароли EAP (проходит успешно), остановка на том же месте.

Привожу конфиги и лог: cat ipsec.conf

# ipsec.conf - strongSwan IPsec configuration file

# basic configuration

conn %default
        left=me_external_static_ip
	leftsubnet=0.0.0.0/0
        leftcert=/etc/strongswan/ipsec.d/certs/server.XXX.by_key.pem
	leftid="C=by, ST=Belarus, O=XXX.by, CN=XXX.by"
	auto=add

conn IPSEC_NAT-T_eap
        right=%any
        rightsubnet=192.168.2.0/24
        rightauth=eap-mschapv2
        eap_identity=%any
        auto=start

conn IPSEC_NAT-T_certs
        right=%any
	rightsourceip=10.0.7.40/27
        auto=start
cat ipsec.secrets
: RSA /etc/strongswan/ipsec.d/private/server.XXX.by_cert.pem "me_pass"
me_user : EAP "me_pass"
(домен и статический ип затер) ну и самое интересное - логи с момента перезапуска:
Sep 16 19:55:26 00[DMN] signal of type SIGINT received. Shutting down
Sep 16 19:55:28 00[DMN] Starting IKE charon daemon (strongSwan 5.0.4, Linux 2.6.32-358.18.1.el6.x86_64, x86_64)
Sep 16 19:55:28 00[LIB] plugin 'sqlite' failed to load: /usr/lib64/strongswan/plugins/libstrongswan-sqlite.so: cannot open shared object file: No such file or directory
Sep 16 19:55:28 00[LIB] openssl FIPS mode(0) - disabled 
Sep 16 19:55:28 00[LIB] plugin 'eap-radius' failed to load: /usr/lib64/strongswan/plugins/libstrongswan-eap-radius.so: cannot open shared object file: No such file or directory
Sep 16 19:55:28 00[LIB] plugin 'eap-tnc' failed to load: /usr/lib64/strongswan/plugins/libstrongswan-eap-tnc.so: cannot open shared object file: No such file or directory
Sep 16 19:55:28 00[LIB] plugin 'tnc-imc' failed to load: /usr/lib64/strongswan/plugins/libstrongswan-tnc-imc.so: cannot open shared object file: No such file or directory
Sep 16 19:55:28 00[LIB] plugin 'tnc-imv' failed to load: /usr/lib64/strongswan/plugins/libstrongswan-tnc-imv.so: cannot open shared object file: No such file or directory
Sep 16 19:55:28 00[LIB] plugin 'tnc-tnccs' failed to load: /usr/lib64/strongswan/plugins/libstrongswan-tnc-tnccs.so: cannot open shared object file: No such file or directory
Sep 16 19:55:28 00[LIB] plugin 'tnccs-20' failed to load: /usr/lib64/strongswan/plugins/libstrongswan-tnccs-20.so: cannot open shared object file: No such file or directory
Sep 16 19:55:28 00[LIB] plugin 'tnccs-11' failed to load: /usr/lib64/strongswan/plugins/libstrongswan-tnccs-11.so: cannot open shared object file: No such file or directory
Sep 16 19:55:28 00[LIB] plugin 'tnccs-dynamic' failed to load: /usr/lib64/strongswan/plugins/libstrongswan-tnccs-dynamic.so: cannot open shared object file: No such file or directory
Sep 16 19:55:28 00[CFG] loading ca certificates from '/etc/strongswan/ipsec.d/cacerts'
Sep 16 19:55:28 00[CFG]   loaded ca certificate "C=by, ST=Belarus, L=Minsk, O=XXX.by, OU=XXX.by, CN=Root CA of XXX.by, E=admin@XXX.by" from '/etc/strongswan/ipsec.d/cacerts/XXX.by_CA_cert.pem'
Sep 16 19:55:28 00[CFG] loading aa certificates from '/etc/strongswan/ipsec.d/aacerts'
Sep 16 19:55:28 00[CFG] loading ocsp signer certificates from '/etc/strongswan/ipsec.d/ocspcerts'
Sep 16 19:55:28 00[CFG] loading attribute certificates from '/etc/strongswan/ipsec.d/acerts'
Sep 16 19:55:28 00[CFG] loading crls from '/etc/strongswan/ipsec.d/crls'
Sep 16 19:55:28 00[CFG] loading secrets from '/etc/strongswan/ipsec.secrets'
Sep 16 19:55:28 00[CFG]   loaded RSA private key from '/etc/strongswan/ipsec.d/private/server.XXX.by_key.pem'
Sep 16 19:55:28 00[CFG]   loaded EAP secret for user
Sep 16 19:55:28 00[DMN] loaded plugins: charon curl aes des sha1 sha2 md4 md5 random nonce x509 revocation constraints pubkey pkcs1 pkcs8 pgp dnskey pem openssl fips-prf gmp xcbc cmac hmac attr kernel-netlink resolve socket-default farp stroke updown eap-identity eap-md5 eap-gtc eap-mschapv2 eap-tls eap-ttls eap-peap xauth-generic xauth-eap dhcp
Sep 16 19:55:28 00[JOB] spawning 16 worker threads
Sep 16 19:55:28 09[CFG] received stroke: add connection 'IPSEC_NAT-T_eap'
Sep 16 19:55:28 09[CFG]   loaded certificate "C=by, ST=Belarus, O=XXX.by, CN=XXX.by" from '/etc/strongswan/ipsec.d/certs/server.XXX.by_cert.pem'
Sep 16 19:55:28 09[CFG] added configuration 'IPSEC_NAT-T_eap'
Sep 16 19:55:28 12[CFG] received stroke: initiate 'IPSEC_NAT-T_eap'
Sep 16 19:55:28 12[IKE] unable to initiate to %any
Sep 16 19:55:28 12[MGR] tried to check-in and delete nonexisting IKE_SA
Sep 16 19:55:28 11[CFG] received stroke: add connection 'IPSEC_NAT-T_certs'
Sep 16 19:55:28 11[CFG] adding virtual IP address pool 10.0.7.40/27
Sep 16 19:55:28 11[CFG]   loaded certificate "C=by, ST=Belarus, O=XXX.by, CN=XXX.by" from '/etc/strongswan/ipsec.d/certs/server.XXX.by_cert.pem'
Sep 16 19:55:28 11[CFG] added configuration 'IPSEC_NAT-T_certs'
Sep 16 19:55:28 15[CFG] received stroke: initiate 'IPSEC_NAT-T_certs'
Sep 16 19:55:28 15[IKE] unable to initiate to %any
Sep 16 19:55:28 15[MGR] tried to check-in and delete nonexisting IKE_SA
и сам момент подключения, разделил для удобства
Sep 16 19:58:31 09[NET] received packet: from 93.125.67.53[500] to me_external_static_ip[500] (616 bytes)
Sep 16 19:58:31 09[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) V V V V ]
Sep 16 19:58:31 09[ENC] received unknown vendor ID: 1e:2b:51:69:05:99:1c:7d:7c:96:fc:bf:b5:87:e4:61:00:00:00:09
Sep 16 19:58:31 09[ENC] received unknown vendor ID: fb:1d:e3:cd:f3:41:b7:ea:16:b7:e5:be:08:55:f1:20
Sep 16 19:58:31 09[ENC] received unknown vendor ID: 26:24:4d:38:ed:db:61:b3:17:2a:36:e3:d0:cf:b8:19
Sep 16 19:58:31 09[ENC] received unknown vendor ID: 01:52:8b:bb:c0:06:96:12:18:49:ab:9a:1c:5b:2a:51:00:00:00:02
Sep 16 19:58:31 09[IKE] 93.125.67.53 is initiating an IKE_SA
Sep 16 19:58:31 09[IKE] remote host is behind NAT
Sep 16 19:58:31 09[IKE] sending cert request for "C=by, ST=Belarus, L=Minsk, O=XXX.by, OU=XXX.by, CN=Root CA of XXX.by, E=admin@XXX.by"
Sep 16 19:58:31 09[ENC] generating IKE_SA_INIT response 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) CERTREQ N(MULT_AUTH) ]
Sep 16 19:58:31 09[NET] sending packet: from me_external_static_ip[500] to 93.125.67.53[500] (333 bytes)
Sep 16 19:58:32 14[NET] received packet: from 93.125.67.53[4500] to me_external_static_ip[4500] (2268 bytes)
Sep 16 19:58:32 14[ENC] parsed IKE_AUTH request 1 [ IDi CERT CERTREQ AUTH N(MOBIKE_SUP) CP(ADDR DNS NBNS SRV) SA TSi TSr ]
Sep 16 19:58:32 14[IKE] received cert request for "C=by, ST=Belarus, L=Minsk, O=XXX.by, OU=XXX.by, CN=Root CA of XXX.by, E=admin@XXX.by"
Sep 16 19:58:32 14[IKE] received 33 cert requests for an unknown ca
Sep 16 19:58:32 14[IKE] received end entity cert "C=by, ST=Belarus, O=XXX.by, OU=XXX.by, CN=bender.XXX.by"
Sep 16 19:58:32 14[CFG] looking for peer configs matching me_external_static_ip[%any]...93.125.67.53[C=by, ST=Belarus, O=XXX.by, OU=XXX.by, CN=bender.XXX.by]
Sep 16 19:58:32 14[CFG] selected peer config 'IPSEC_NAT-T_eap'
Sep 16 19:58:32 14[CFG]   using certificate "C=by, ST=Belarus, O=XXX.by, OU=XXX.by, CN=bender.XXX.by"
Sep 16 19:58:32 14[CFG]   using trusted ca certificate "C=by, ST=Belarus, L=Minsk, O=XXX.by, OU=XXX.by, CN=Root CA of XXX.by, E=admin@XXX.by"
Sep 16 19:58:32 14[CFG] checking certificate status of "C=by, ST=Belarus, O=XXX.by, OU=XXX.by, CN=bender.XXX.by"
Sep 16 19:58:32 14[CFG] certificate status is not available
Sep 16 19:58:32 14[CFG]   reached self-signed root ca with a path length of 0
Sep 16 19:58:32 14[IKE] authentication of 'C=by, ST=Belarus, O=XXX.by, OU=XXX.by, CN=bender.XXX.by' with RSA signature successful
Sep 16 19:58:32 14[CFG] constraint check failed: EAP identity '%any' required 
Sep 16 19:58:32 14[CFG] selected peer config 'IPSEC_NAT-T_eap' inacceptable: non-matching authentication done
Sep 16 19:58:32 14[CFG] switching to peer config 'IPSEC_NAT-T_certs'
Sep 16 19:58:32 14[IKE] peer supports MOBIKE
Sep 16 19:58:32 14[IKE] authentication of 'C=by, ST=Belarus, O=XXX.by, CN=XXX.by' (myself) with RSA signature successful
Sep 16 19:58:32 14[IKE] IKE_SA IPSEC_NAT-T_certs[3] established between me_external_static_ip[C=by, ST=Belarus, O=XXX.by, CN=XXX.by]...93.125.67.53[C=by, ST=Belarus, O=XXX.by, OU=XXX.by, CN=bender.XXX.by]
Sep 16 19:58:32 14[IKE] scheduling reauthentication in 10205s
Sep 16 19:58:32 14[IKE] maximum IKE_SA lifetime 10745s
Sep 16 19:58:32 14[IKE] sending end entity cert "C=by, ST=Belarus, O=XXX.by, CN=XXX.by"
Sep 16 19:58:32 14[IKE] peer requested virtual IP %any
Sep 16 19:58:32 14[CFG] assigning new lease to 'C=by, ST=Belarus, O=XXX.by, OU=XXX.by, CN=bender.XXX.by'
Sep 16 19:58:32 14[IKE] assigning virtual IP 10.0.7.41 to peer 'C=by, ST=Belarus, O=XXX.by, OU=XXX.by, CN=bender.XXX.by'
Sep 16 19:58:32 14[IKE] CHILD_SA IPSEC_NAT-T_certs{1} established with SPIs cbfb8f34_i 16ca58d8_o and TS 0.0.0.0/0 === 10.0.7.41/32 
Sep 16 19:58:32 14[ENC] generating IKE_AUTH response 1 [ IDr CERT AUTH CP(ADDR DNS NBNS) SA TSi TSr N(AUTH_LFT) N(MOBIKE_SUP) N(ADD_4_ADDR) N(ADD_4_ADDR) ]
Sep 16 19:58:32 14[NET] sending packet: from me_external_static_ip[4500] to 93.125.67.53[4500] (1540 bytes)
Это все, дальше этого просто не идет. Прошу помощи у сообщества ) помогите решить ))

 , , , ,

vaga
()

ipsec (openswan) + l2tp (xl2tpd) + win клиент = проблема

Форум — Admin

День добрый. Помогите решить проблему, ибо сам уже не знаю куда копать, гуглил-перегуглил, маны и прочее, в большинстве случаев конфиги везде одинаковые. Нуждаюсь в подсказке или указании направления. Имеется: Centos 6.3, iptables + маскарад, ipsec (пакет openswan-2.6.32-18.el6_3.i686 - вместе с осью) и l2tp (пакет xl2tpd-1.3.1-4.el6.i686 - ставил из реп через yum), ppp (ppp-2.4.5-5.el6.i686 - вместе с осью при установке). Обновлений yum не находит. Задача заставить это все работать с вин клиентом. Про nat-t в курсе, про ключ в реестре вин в курсе. Самое интересное, что судя по логам ipsec канал создается без проблем (в этом, как я понимаю, вся сложность из за ната), а дальше тишина, l2tp как будто и не пытается устанавливать свой канал. По локалке все работает. Порты 500, 4500 и -p 50 открыты. В логах я не вижу ничего от l2tp, потому и говорю что «тишина». В линухах я, в общем то, нуб, недели 3 как на домашнем серве поставил эту ось и настроил, система очень нравиться :) Конфиги и логи прилагаются.

Схема сети: LAN (10.0.7.0/26) ---- [10.0.7.1 CentOS nat ppp0 (шлюз)] ------ интернет ---- [nat] ----win l2tp client (ип любой)

cat /var/log/secure

Sep  3 17:54:01 server pluto[31126]: packet from 178.127.118.208:64464: ignoring Vendor ID payload [MS NT5 ISAKMPOAKLEY 00000008]
Sep  3 17:54:01 server pluto[31126]: packet from 178.127.118.208:64464: received Vendor ID payload [RFC 3947] method set to=109 
Sep  3 17:54:01 server pluto[31126]: packet from 178.127.118.208:64464: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n] meth=106, but already using method 109
Sep  3 17:54:01 server pluto[31126]: packet from 178.127.118.208:64464: ignoring Vendor ID payload [FRAGMENTATION]
Sep  3 17:54:01 server pluto[31126]: packet from 178.127.118.208:64464: ignoring Vendor ID payload [MS-Negotiation Discovery Capable]
Sep  3 17:54:01 server pluto[31126]: packet from 178.127.118.208:64464: ignoring Vendor ID payload [Vid-Initial-Contact]
Sep  3 17:54:01 server pluto[31126]: packet from 178.127.118.208:64464: ignoring Vendor ID payload [IKE CGA version 1]
Sep  3 17:54:01 server pluto[31126]: "L2TP-PSK-NAT"[12] 178.127.118.208 #12: responding to Main Mode from unknown peer 178.127.118.208
Sep  3 17:54:01 server pluto[31126]: "L2TP-PSK-NAT"[12] 178.127.118.208 #12: OAKLEY_GROUP 20 not supported.  Attribute OAKLEY_GROUP_DESCRIPTION
Sep  3 17:54:01 server pluto[31126]: "L2TP-PSK-NAT"[12] 178.127.118.208 #12: OAKLEY_GROUP 19 not supported.  Attribute OAKLEY_GROUP_DESCRIPTION
Sep  3 17:54:01 server pluto[31126]: "L2TP-PSK-NAT"[12] 178.127.118.208 #12: transition from state STATE_MAIN_R0 to state STATE_MAIN_R1
Sep  3 17:54:01 server pluto[31126]: "L2TP-PSK-NAT"[12] 178.127.118.208 #12: STATE_MAIN_R1: sent MR1, expecting MI2
Sep  3 17:54:01 server pluto[31126]: "L2TP-PSK-NAT"[12] 178.127.118.208 #12: NAT-Traversal: Result using RFC 3947 (NAT-Traversal): peer is NATed
Sep  3 17:54:01 server pluto[31126]: "L2TP-PSK-NAT"[12] 178.127.118.208 #12: transition from state STATE_MAIN_R1 to state STATE_MAIN_R2
Sep  3 17:54:01 server pluto[31126]: "L2TP-PSK-NAT"[12] 178.127.118.208 #12: STATE_MAIN_R2: sent MR2, expecting MI3
Sep  3 17:54:02 server pluto[31126]: "L2TP-PSK-NAT"[12] 178.127.118.208 #12: Main mode peer ID is ID_IPV4_ADDR: '192.168.0.7'
Sep  3 17:54:02 server pluto[31126]: "L2TP-PSK-NAT"[12] 178.127.118.208 #12: switched from "L2TP-PSK-NAT" to "L2TP-PSK-NAT"
Sep  3 17:54:02 server pluto[31126]: "L2TP-PSK-NAT"[13] 178.127.118.208 #12: deleting connection "L2TP-PSK-NAT" instance with peer 178.127.118.208 {isakmp=#0/ipsec=#0}
Sep  3 17:54:02 server pluto[31126]: "L2TP-PSK-NAT"[13] 178.127.118.208 #12: transition from state STATE_MAIN_R2 to state STATE_MAIN_R3
Sep  3 17:54:02 server pluto[31126]: "L2TP-PSK-NAT"[13] 178.127.118.208 #12: new NAT mapping for #12, was 178.127.118.208:64464, now 178.127.118.208:62687
Sep  3 17:54:02 server pluto[31126]: "L2TP-PSK-NAT"[13] 178.127.118.208 #12: STATE_MAIN_R3: sent MR3, ISAKMP SA established {auth=OAKLEY_PRESHARED_KEY cipher=aes_256 prf=oakley_sha group=modp2048}
Sep  3 17:54:02 server pluto[31126]: "L2TP-PSK-NAT"[13] 178.127.118.208 #12: the peer proposed: 178.127.57.89/32:17/1701 -> 192.168.0.7/32:17/0
Sep  3 17:54:02 server pluto[31126]: "L2TP-PSK-NAT"[13] 178.127.118.208 #12: peer proposal was reject in a virtual connection policy because:
Sep  3 17:54:02 server pluto[31126]: "L2TP-PSK-NAT"[13] 178.127.118.208 #12:   a private network virtual IP was required, but the proposed IP did not match our list (virtual_private=)
Sep  3 17:54:02 server pluto[31126]: "L2TP-PSK-NAT"[13] 178.127.118.208 #12: peer proposal was reject in a virtual connection policy because:
Sep  3 17:54:02 server pluto[31126]: "L2TP-PSK-NAT"[13] 178.127.118.208 #12:   a private network virtual IP was required, but the proposed IP did not match our list (virtual_private=)
Sep  3 17:54:02 server pluto[31126]: "L2TP-PSK-NAT"[13] 178.127.118.208 #12: NAT-Traversal: received 2 NAT-OA. using first, ignoring others
Sep  3 17:54:02 server pluto[31126]: "L2TP-PSK-NAT"[13] 178.127.118.208 #13: responding to Quick Mode proposal {msgid:01000000}
Sep  3 17:54:02 server pluto[31126]: "L2TP-PSK-NAT"[13] 178.127.118.208 #13:     us: 178.127.57.89[+S=C]:17/1701
Sep  3 17:54:02 server pluto[31126]: "L2TP-PSK-NAT"[13] 178.127.118.208 #13:   them: 178.127.118.208[192.168.0.7,+S=C]:17/1701===192.168.0.7/32
Sep  3 17:54:02 server pluto[31126]: "L2TP-PSK-NAT"[13] 178.127.118.208 #13: transition from state STATE_QUICK_R0 to state STATE_QUICK_R1
Sep  3 17:54:02 server pluto[31126]: "L2TP-PSK-NAT"[13] 178.127.118.208 #13: STATE_QUICK_R1: sent QR1, inbound IPsec SA installed, expecting QI2
Sep  3 17:54:02 server pluto[31126]: "L2TP-PSK-NAT"[13] 178.127.118.208 #13: transition from state STATE_QUICK_R1 to state STATE_QUICK_R2
Sep  3 17:54:02 server pluto[31126]: "L2TP-PSK-NAT"[13] 178.127.118.208 #13: STATE_QUICK_R2: IPsec SA established transport mode {ESP=>0x96537d66 <0x5a8cfa2f xfrm=AES_128-HMAC_SHA1 NATOA=192.168.0.7 NATD=178.127.118.208:62687 DPD=none}
Sep  3 17:54:09 server pluto[31126]: "L2TP-PSK-NAT"[13] 178.127.118.208 #12: received Delete SA(0x96537d66) payload: deleting IPSEC State #13
Sep  3 17:54:09 server pluto[31126]: "L2TP-PSK-NAT"[13] 178.127.118.208 #12: ERROR: netlink XFRM_MSG_DELPOLICY response for flow eroute_connection delete included errno 2: No such file or directory
Sep  3 17:54:09 server pluto[31126]: "L2TP-PSK-NAT"[13] 178.127.118.208 #12: received and ignored informational message
Sep  3 17:54:09 server pluto[31126]: "L2TP-PSK-NAT"[13] 178.127.118.208 #12: received Delete SA payload: deleting ISAKMP State #12
Sep  3 17:54:09 server pluto[31126]: "L2TP-PSK-NAT"[13] 178.127.118.208: deleting connection "L2TP-PSK-NAT" instance with peer 178.127.118.208 {isakmp=#0/ipsec=#0}
Sep  3 17:54:09 server pluto[31126]: packet from 178.127.118.208:62687: received and ignored informational message
по логу видна задержка 17:54:02 - 17:54:09, хотя обычно этот промежуток 20-30 сек. В логах SElinux ничего не вижу подозрительного, не привожу их. Лог xl2tpd вообще какой то странный и он не обновляется кажется. Вероятно, он создавался, когда я соединялся из локальной сети.
cat /var/log/xl2tpd.log
using channel 2
Using interface ppp1
Connect: ppp1 <--> /dev/pts/2
sent [LCP ConfReq id=0x1 <mru 1200> <asyncmap 0x0> <auth chap MD5> <magic 0xa73090bc> <pcomp> <accomp>]
rcvd [LCP ConfNak id=0x1 <auth chap MS-v2>]
sent [LCP ConfReq id=0x2 <mru 1200> <asyncmap 0x0> <auth chap MS-v2> <magic 0xa73090bc> <pcomp> <accomp>]
rcvd [LCP ConfAck id=0x2 <mru 1200> <asyncmap 0x0> <auth chap MS-v2> <magic 0xa73090bc> <pcomp> <accomp>]
rcvd [LCP ConfReq id=0x1 <mru 1400> <magic 0x53a923ea> <pcomp> <accomp> <callback CBCP>]
sent [LCP ConfRej id=0x1 <callback CBCP>]
rcvd [LCP ConfReq id=0x2 <mru 1400> <magic 0x53a923ea> <pcomp> <accomp>]
sent [LCP ConfAck id=0x2 <mru 1400> <magic 0x53a923ea> <pcomp> <accomp>]
sent [CHAP Challenge id=0x8f <4c9a7e6904d4f2cf2e487ee51e5e9521>, name = "OpenswanVPN"]
rcvd [LCP Ident id=0x3 magic=0x53a923ea "MSRASV5.20"]
rcvd [LCP Ident id=0x4 magic=0x53a923ea "MSRAS-0-BENDER"]
rcvd [LCP Ident id=0x5 magic=0x53a923ea "\001\37777777651\37777777727\37777777700\377777776435JC\37777777654\37777777607\37777777762=v\37777777737&="]
rcvd [CHAP Response id=0x8f <3eb30aa3c11c83e5816e2a00b9fc41e70000000000000000a2f36a8b01a7e8f30b804c94a8456d7cf24188c4483285be00>, name = "user"]
sent [CHAP Success id=0x8f "S=41512281923BEC6C11E35D732D9720A038F846E6 M=Access granted"]
sent [IPCP ConfReq id=0x1 <compress VJ 0f 01> <addr 10.0.7.9>]
rcvd [CCP ConfReq id=0x6 <mppe +H -M -S -L -D -C>]
Unsupported protocol 'Compression Control Protocol' (0x80fd) received
sent [LCP ProtRej id=0x3 80 fd 01 06 00 0a 12 06 01 00 00 00]
rcvd [IPCP ConfReq id=0x7 <addr 0.0.0.0> <ms-dns1 0.0.0.0> <ms-wins 0.0.0.0> <ms-dns2 0.0.0.0> <ms-wins 0.0.0.0>]
sent [IPCP ConfRej id=0x7 <ms-dns1 0.0.0.0> <ms-wins 0.0.0.0> <ms-dns2 0.0.0.0> <ms-wins 0.0.0.0>]
rcvd [IPCP ConfRej id=0x1 <compress VJ 0f 01>]
sent [IPCP ConfReq id=0x2 <addr 10.0.7.9>]
rcvd [IPCP ConfReq id=0x8 <addr 0.0.0.0>]
sent [IPCP ConfNak id=0x8 <addr 10.0.7.40>]
rcvd [IPCP ConfAck id=0x2 <addr 10.0.7.9>]
rcvd [IPCP ConfReq id=0x9 <addr 10.0.7.40>]
sent [IPCP ConfAck id=0x9 <addr 10.0.7.40>]
found interface eth1 for proxy arp
local  IP address 10.0.7.9
remote IP address 10.0.7.40
Script /etc/ppp/ip-up started (pid 20404)
Script /etc/ppp/ip-up finished (pid 20404), status = 0x0
rcvd [LCP TermReq id=0xa "S\37777777651#\37777777752\000<\37777777715t\000\000\000\000"]
LCP terminated by peer (SM-)#M-j^@<M-Mt^@^@^@^@)
Connect time 1.9 minutes.
Sent 0 bytes, received 29620 bytes.
Script /etc/ppp/ip-down started (pid 20416)
sent [LCP TermAck id=0xa]
using channel 3
Using interface ppp1
Connect: ppp1 <--> /dev/pts/2
sent [LCP ConfReq id=0x1 <mru 1200> <asyncmap 0x0> <auth chap MD5> <magic 0xe0248135> <pcomp> <accomp>]
rcvd [LCP ConfReq id=0x0 <mru 1400> <magic 0x42144065> <pcomp> <accomp> <callback CBCP>]
sent [LCP ConfRej id=0x0 <callback CBCP>]
rcvd [LCP ConfNak id=0x1 <auth chap MS-v2>]
sent [LCP ConfReq id=0x2 <mru 1200> <asyncmap 0x0> <auth chap MS-v2> <magic 0xe0248135> <pcomp> <accomp>]
rcvd [LCP ConfReq id=0x1 <mru 1400> <magic 0x42144065> <pcomp> <accomp>]
sent [LCP ConfAck id=0x1 <mru 1400> <magic 0x42144065> <pcomp> <accomp>]
rcvd [LCP ConfAck id=0x2 <mru 1200> <asyncmap 0x0> <auth chap MS-v2> <magic 0xe0248135> <pcomp> <accomp>]
sent [CHAP Challenge id=0x97 <715d61f11dfab46bd1e3abf458384962>, name = "OpenswanVPN"]
rcvd [LCP Ident id=0x2 magic=0x42144065 "MSRASV5.20"]
rcvd [LCP Ident id=0x3 magic=0x42144065 "MSRAS-0-BENDER"]
rcvd [LCP Ident id=0x4 magic=0x42144065 "E\37777777675\37777777634)\37777777725&\37777777764N\37777777646\37777777663\37777777666j\37777777606JtM"]
rcvd [CHAP Response id=0x97 <4623b7ac0df9acf7a7b89fd4643938820000000000000000c1d14fa3858edbe84c9487f04eb64644e70479286b9fb40900>, name = "user"]
sent [CHAP Success id=0x97 "S=208A98485ECC66496BD0668A3CA870DD6541637B M=Access granted"]
sent [IPCP ConfReq id=0x1 <compress VJ 0f 01> <addr 10.0.7.2>]
rcvd [CCP ConfReq id=0x5 <mppe +H -M -S -L -D -C>]
Unsupported protocol 'Compression Control Protocol' (0x80fd) received
sent [LCP ProtRej id=0x3 80 fd 01 05 00 0a 12 06 01 00 00 00]
rcvd [IPCP ConfReq id=0x6 <addr 0.0.0.0> <ms-dns1 0.0.0.0> <ms-wins 0.0.0.0> <ms-dns2 0.0.0.0> <ms-wins 0.0.0.0>]
sent [IPCP ConfRej id=0x6 <ms-dns1 0.0.0.0> <ms-wins 0.0.0.0> <ms-dns2 0.0.0.0> <ms-wins 0.0.0.0>]
rcvd [IPCP ConfRej id=0x1 <compress VJ 0f 01>]
sent [IPCP ConfReq id=0x2 <addr 10.0.7.2>]
rcvd [IPCP ConfReq id=0x7 <addr 0.0.0.0>]
sent [IPCP ConfNak id=0x7 <addr 10.0.7.40>]
rcvd [IPCP ConfAck id=0x2 <addr 10.0.7.2>]
rcvd [IPCP ConfReq id=0x8 <addr 10.0.7.40>]
sent [IPCP ConfAck id=0x8 <addr 10.0.7.40>]
found interface eth1 for proxy arp
local  IP address 10.0.7.2
remote IP address 10.0.7.40
Script /etc/ppp/ip-up started (pid 20461)
Script /etc/ppp/ip-up finished (pid 20461), status = 0x0
rcvd [LCP TermReq id=0x9 "B\024@e\000<\37777777715t\000\000\000\000"]
LCP terminated by peer (B^T@e^@<M-Mt^@^@^@^@)
Connect time 16.7 minutes.
Sent 0 bytes, received 45566 bytes.
Script /etc/ppp/ip-down started (pid 20579)
sent [LCP TermAck id=0x9]
Modem hangup
Connection terminated.
Конфиги:
cat /etc/ipsec.conf
version    2.0    # conforms to second version of ipsec.conf specification

config setup
        nat_traversal=yes
        virtual_private=%v4:10.0.0.0/8,%v4:172.16.0.0/12,%v4:192.168.0.0/16,%v4:!10.0.7.0/26
        protostack=netkey
        interfaces=%defaultroute
        oe=off
conn L2TP-PSK-NAT
        authby=secret
	type=transport
        pfs=no
        rekey=no
        keyingtries=3
        left=%defaultroute
        leftprotoport=17/1701
        right=%any
        rightsubnet=vhost:%no,%priv
        rightprotoport=17/%any
        auto=add

cat /etc/ipsec.d/ip
10.0.7.1  %any: PSK "myipsecpass"

cat /etc/xl2tpd/xl2tpd.conf
ipsec saref = yes
debug tunnel = yes
debug avp = yes
debug network = yes
debug packet = yes
debug state = yes
;force userspace =yes

[lns default]
ip range = 10.0.7.40-10.0.7.50
local ip = 10.0.7.2
assign ip = yes
require chap = yes
refuse pap = yes
require authentication = yes
name = l2tpVPN
ppp debug = yes
pppoptfile = /etc/ppp/options.xl2tpd
length bit = yes

cat /etc/ppp/options.xl2tpd
ipcp-accept-local
ipcp-accept-remote
require-mschap-v2
auth
noccp
idle 1800
mtu 1200
mru 1200
nodefaultroute
debug
lock
proxyarp
connect-delay 5000
logfile /var/log/xl2tpd.log
cat /etc/ppp/chap-secrets
"user"	 l2tpVPN	"mypass"	*
в логах /var/log/messages от xl2tpd пусто (не привожу его, ибо там нет ничего с этим связанного, кроме флуда от snmpd, котрый я пока хз как откл), более того rsyslog настроен на вывод сообщений от даемонов в отдельный файл, там тоже пусто от xl2tpd. Чувствую, что ошибка в чем то мелком, но сам уже запарился, подскажите кто видит ошибку :)

 , ,

vaga
()

RSS подписка на новые темы